
TLDR
Leaked internal instructions show Meta's Muse AI agent compiles hourly dossiers on users and people in their networks, including non-users who never consented. Meta did not dispute the findings. From 10 December 2026, Australian privacy law will require organisations to say in their privacy policies when computer programs use personal information to make decisions that significantly affect people.
Hourly profiles, silent on deleted messages
Internal instructions obtained by TIME show Muse builds continuously updated dossiers on its users and on people in their networks, including individuals who have never held a Meta account and never agreed to be profiled.[1] The same instructions tell Muse to stay quiet about the fact that messages a user believes deleted may still persist in the system.[1]
Meta was approached for comment and did not dispute the report.[1]
What Meta launched and how fast it grew
Meta launched Muse on 8 September 2026, describing it as a secure, private personal AI agent that proactively helps with people's goals and suggests ideas.[6] Muse runs on a dedicated cloud environment called Muse Secure VM and can send emails, fill forms and negotiate bookings autonomously, requiring explicit user approval only for sensitive actions.[6]
The product reached roughly 3 to 4 million weekly users within weeks of launch, according to The Information and TIME.
The Australian compliance clock
The deadline Australian operators need to mark is 10 December 2026. The Office of the Australian Information Commissioner published new guidance on 30 September 2026 stating that from that date, Australian Privacy Principle entities must include in their privacy policies information about the kinds of personal information used and the decisions made when a computer program makes or substantially informs decisions that significantly affect individuals' rights or interests.[3]
The OAIC's Corporate Plan 2026 to 2027 confirms it is actively developing guidance on the Transparency in Automated Decision-Making reforms commencing December 2026, as part of implementing the Privacy Act changes that began in December 2024.[4] Hourly automated profiling of the kind TIME describes sits squarely within what those reforms target, and Meta's current privacy disclosures, written before Muse existed, were not built with that obligation in mind.
The OAIC has also moved on children's data. Privacy Commissioner Carly Kind said when releasing the Children's Online Privacy Code exposure draft in March 2026 that by the time a child turns 13, around 72 million pieces of data will have been collected about them, making them vulnerable to harms from data breaches, discrimination, algorithmic bias and targeted advertising of harmful products, amongst other risks.[5] An AI agent that profiles a user's entire network will, in many cases, be collecting data on children sitting inside that network.
What operators using Meta's tools need to do now
Any Australian business that has integrated Muse or Meta's AI tools into its customer-facing operations carries a question its legal team should answer before December: does the automated profiling Muse performs on the business's users and their contacts meet the disclosure requirements taking effect on 10 December 2026?[3]
KEY TAKEAWAYS
SOURCES & CITATIONS
FREQUENTLY ASKED QUESTIONS
What does Meta's Muse AI agent actually do with user data?
Did Meta deny the TIME report about Muse's profiling behaviour?
What do Australian privacy laws require of companies like Meta from December 2026?
How many people are using Muse?

Takeshi Mori writes about technology and start-ups. He is curious about how products get built and who they are really for, and he would rather see a thing working than hear it described.




